Slashdot Mirror


Apple Was Notified About Major FaceTime Eavesdropping Bug Over a Week Ago (macrumors.com)

An anonymous reader writes: Twitter user MGT7500 tagged the official Apple Support account in a January 20 tweet claiming that her 14-year-old son discovered a "major security flaw" that allowed him to "listen in to your iPhone/iPad without your approval." The user also tagged Tim Cook on the issue in a follow-up tweet on January 21."

Once the bug started making headlines on Monday, the Twitter user then shared additional tweets claiming that they had also emailed Apple's product security team over a week ago. A screenshot of the email was shared, and it appears the team did respond, but what they said is not visible in the screenshot. [...] All in all, there is evidence that Apple Support was tagged about an eavesdropping bug eight days before it made headlines, and if the rest of the tweets are truthful, the company was also alerted about the bug via several other avenues.
The original story has been updated to include another example of a user -- John Meyer -- who has shared a video about the FaceTime bug that he says was recorded and sent to Apple on January 23.

54 comments

  1. eMail response by Anonymous Coward · · Score: 1

    Take a pick:

    1) No
    2) your security is important to us, here is a link to our FAQ
    3) You're wrong, Apple does not have bugs.

    1. Re: eMail response by Anonymous Coward · · Score: 0

      You are holding it wrong, or maybe this is a courageous move by Apple to remove the legacy answer call button

    2. Re:eMail response by Aighearach · · Score: 1

      My experience, regardless of company, is all three of those at the same time, but using confused wording.

    3. Re:eMail response by Anonymous Coward · · Score: 0

      Thank you for using Apple. If you are having trouble with a product, click here. If you wish to buy more products, click here. If you want to add cloud dependency for any local feature or service, click here.

      This is a generated email, do not reply. To unsubscribe or manage your email subscriptions, click here.

    4. Re:eMail response by zifn4b · · Score: 1

      Studies show obfuscation of the truth is good for company reputations

      --
      We'll make great pets
  2. It's a feature by Anonymous Coward · · Score: 0

    I thought users wanted group facetime?

  3. Tagging? lol by Spy+Handler · · Score: 2, Insightful

    Does Tim Cook actually monitor Twitter and look for posts with a #TIMCOOK tag and then read them?

    Since anyone with an ounce of brain will realize the answer is a big fat NO, shouldn't it also be obvious that tagging a Twitter post with someone's name is completely worthless, and that if you wanna report a fucking bug, you should go to that company's bug reporting website and do it there? Apple has one, it took me all of 2 seconds to Google for it: https://bugreport.apple.com/

    Actually it should be obvious to people by now that Twitter itself is completely worthless. Just let it die, please?

    1. Re:Tagging? lol by darkain · · Score: 3, Informative

      At least RTFS....

      "they had also emailed Apple's product security team over a week ago."

    2. Re: Tagging? lol by Anonymous Coward · · Score: 2, Funny

      They tagged the cook account, the support twitter and emailed the security team.

      What more did you expect them to do? Provide blow jobs?

    3. Re:Tagging? lol by Anonymous Coward · · Score: 0

      I use an iPhone and don't agree with many of Apple's design decisions but this is not in Cook's lane. One week in time to analyze the issue and decide a course of action. Might be to deny it, but engineers are driving that. Apple sucks in many ways, this is not one of them.

    4. Re:Tagging? lol by bobbied · · Score: 1

      Wouldn't that be @timcook?

      I'd be wiling to bet that Apple monitors a number of hash tags related to it's business on Twitter. So you may not get Tim Cook's direct attention, but somebody at Apple is likely scanning for such tags, even if it's just Siri's mainframe based cousin who pays any attention.

      --
      "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
    5. Re:Tagging? lol by Anonymous Coward · · Score: 0

      You might want to rethink all of the assumptions you're making.

    6. Re:Tagging? lol by Anonymous Coward · · Score: 0

      One week to analyze an easily reproducable bug for a multibillion dollar company that requires 0 additional knowledge, skill, and software to duplicate? That's extremely sad. At least most other bugs are those that a malicious person has to explicitly craft. This is a bug anyone can stumble in on.

    7. Re:Tagging? lol by cyn1c77 · · Score: 1

      Does Tim Cook actually monitor Twitter and look for posts with a #TIMCOOK tag and then read them?

      Since anyone with an ounce of brain will realize the answer is a big fat NO, shouldn't it also be obvious that tagging a Twitter post with someone's name is completely worthless, and that if you wanna report a fucking bug, you should go to that company's bug reporting website and do it there? Apple has one, it took me all of 2 seconds to Google for it: https://bugreport.apple.com/

      Actually it should be obvious to people by now that Twitter itself is completely worthless. Just let it die, please?

      Well, maybe he should. It might be good for him to get his head out of his ass, I mean reality distortion field, and see what is actually going on with his products.

      Especially since both the official Apple Support account and product security teams take longer than a week to respond... which basically is non-responsive on a bug of this magnitude.

    8. Re: Tagging? lol by Highdude702 · · Score: 2

      Would probably accelerate the process a bit. Or some process at least.

    9. Re:Tagging? lol by drinkypoo · · Score: 1

      Does Tim Cook actually monitor Twitter and look for posts with a #TIMCOOK tag and then read them?

      No, but if his staff doesn't, Apple is failing at social media. What year is it?

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    10. Re: Tagging? lol by Anonymous Coward · · Score: 0

      Never talk about Apple and Jobs. Especially, no blowing at the same time. Very distasteful to the turtleneck crowd.

    11. Re:Tagging? lol by Anonymous Coward · · Score: 0

      I imagine more like one week to get through all the dross that knuckledraggers flood them with

    12. Re:Tagging? lol by Anonymous Coward · · Score: 0

      Because #courage.

      And also you are reporting the bug wrong.

  4. you are holding it wrong! by kiviQr · · Score: 4, Funny

    ...you need to cover mic and camera with thumb and index finger!

  5. Re:Bug or Feature by bobbied · · Score: 1, Insightful

    Bug or feature for law enforcement etc.?

    This is Apple. Remember their refusal to help unlock the phone of the guy who shot up the staff Christmas party in California awhile back? Yea, they don't seem to be the type to do what ever law enforcement asks.

    Therefore, I'm guessing this is a "bug" and not a planned feature. But, it's just a guess.

    --
    "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
  6. Radio silence by mrobinso · · Score: 1

    It's obvious that radio silence is the sole MO for large corporate entities, especially the popular / well-known ones. Saying nothing is not the same as denying, and won't be until government bodies start prosecuting it that way.

    And sure, Twitter is mostly worthless, but at least they don't make a living and pay high dividends to the 1%'ers by selling way over-priced offshore-made proprietary whatchamacallits.

    --
    -- Karma whore? You betcha. --
  7. AAPL EARNINGS TANK! by Anonymous Coward · · Score: 0

    Down 28%. My GOD! We're doomed! Thanks, Trump!

  8. Do you want it fixed right or not? by SuperKendall · · Score: 1

    Even reporting to the security team as it was, would probably take a day or so to verify, and then someone can be assigned to fix...

    But let's be realistic, a fix for this is not something that would just take overnight - or not something you would want them to rush. I mean, do you want it fixed right or do you want some new bug introduced?

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:Do you want it fixed right or not? by Anonymous Coward · · Score: 0

      Depending on the software architecture it may be trivial to enable or disable features, without inside information we don't know if they need to "rush" anything or not.

    2. Re: Do you want it fixed right or not? by Anonymous Coward · · Score: 0

      Fix seems simple, stop user from adding themselves to the chat

  9. Clearly... by Vegan+Cyclist · · Score: 1

    ...Apple was holding their phone wrong when the email came in.

  10. Re:Bug or Feature by ZenShadow · · Score: 1

    That's just what they want you to think...

    --
    -- sigs cause cancer.
  11. Nothing new here by Anonymous Coward · · Score: 0

    Apple won't recognise `bugs' in its perfect OS unless they go viral.

  12. Already patched (just spoke to Apple's people) by Anonymous Coward · · Score: 1

    Already patched (just spoke to Apple's people - DIRECTLY - & the ones doing the patchwork whom I know (my nephew practically "runs the show" in that very dept. for them for 6++ yrs. now so I get a 'direct line'...)).

    Currently - He's on their "tiger teams" now though but is aware it is patched (not many of you will KNOW what a 'tiger team' is but you have to be REALLY GOOD to be on one). I'm proud of his achievements in fact, especially THAT one.

    * Soooo, "Move along folks - nothing to see here" & I noted this here already https://apple.slashdot.org/com...

    APK

    P.S.=> They're pretty QUICK on the mark on this note in patches - NOW, it's just waiting on "Q/A" personnel stamp of approval turn-around time... apk

    1. Re:Already patched (just spoke to Apple's people) by Anonymous Coward · · Score: 0

      In traditional apple style this patch will introduce several new bugs.

    2. Re:Already patched (just spoke to Apple's people) by Anonymous Coward · · Score: 0

      This reads like it was written by someone on Apple's marketing team.

      I seriously doubt Apple developers can talk about what they are working on considering I wasn't even allowed to visit Apple HQ in Australia without signing an NDA, or join development events without signing an NDA.

      So at the very least, it sounds like he's acting like he's running the show I'm guessing.

    3. Re:Already patched (just spoke to Apple's people) by Anonymous Coward · · Score: 0

      Can you ask them to bring back the quality? It seems to have gone with their older programmers who mostly retired or were forced out over the last 10 years.

  13. Why "bug" instead of "security flaw" by Anonymous Coward · · Score: 0

    Anyone know why the press narrative shifted to describe this security flaw/issue as a "bug"?

    Isn't this "bug" the very type that also qualifies as a security flaw? (all security flaws qualify as bugs, but not all bugs are special enough to qualify as a security flaw)

  14. Apple support wanted to spy on mom for a week by Anonymous Coward · · Score: 0

    But Mom was too clever for them and they had to give up.

  15. Well, let's hope not... apk by Anonymous Coward · · Score: 0

    Well, let's hope not for Apple's users @ least - bugs, suck! Me? I don't write "bugs" (e.g. none found in my hosts engine to date w/ 100k++ users worldwide).

    APK

    P.S.=> I think a BIG part of why is that, when possible, I don't tend to depend on others' libs etc. (what you can't control, a BIG one that) - just my own code & that of the compiler + OS API's I use (helps stall the possibility of 'bugs' that way & so far for me, since 1982 coding here? It's done well)... apk

    1. Re:Well, let's hope not... apk by Anonymous Coward · · Score: 0

      Does your source code look anything like your English messages?
      Because your messages look like multilevel marketing scam clickbait, with nested double parentheses.

        “I earn OVER $5000 per DAY (not week) and I get to do it in my OWN LOUNGE. (PS=> this is NOT a scam!!!)”

      etc

  16. Re:Bug or Feature by drinkypoo · · Score: 1

    This is Apple. Remember their refusal to help unlock the phone of the guy who shot up the staff Christmas party in California awhile back? Yea, they don't seem to be the type to do what ever law enforcement asks.

    That's what the press releases say, so it must be true!

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  17. Black gaffers tape. by Anonymous Coward · · Score: 0

    Getting the residue back off is a pain, but the shit sticks well for a few weeks before needing replacement.

    If you don't care about color, all kinds of masking tape work, including the low residue varieties, but they are usually in bright contrasting color which will get you labelled one of those 'privacy kooks'.

  18. So pretty much what the spooks can do with Android by Anonymous Coward · · Score: 0

    Remote activation of mic and cam? Pft. Old news. Five eyes been able to do this for about a decade now.

  19. "What happens on your iPhone stays on your iPhone" by tttonyyy · · Score: 1

    No tech company can truly know, for sure, that their product is secure. Shouting this from the rooftops (in this case, pretty much literally) was only ever going to end one way.

    https://www.independent.co.uk/...

    Pride comes before a fall and all that!

    --
    biopowered.co.uk - catalytically cracking triglycerides for home automotive use since 2008. Just say no to big oil!
  20. Re:Bug or Feature by bobbied · · Score: 1

    So, if the press coverage all disagrees with your version of events, Just ignore it and go with your version? Even when there are legal rulings and transcripts that support the news reporting?

    Why bother complaining about Fake News when we have stuff like this..

    --
    "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
  21. Re:Bug or Feature by drinkypoo · · Score: 1

    "Even when there are legal rulings and transcripts that support the news reporting?"

    A transcript can contain lies, that's literally what corporate lawyers and PR flacks are for. A court can be misled. Until the OS is OSS, you can't even begin to trust it. And all the important bits are closed. You can trust on faith if you want to, but I expect verification. That's why I'm not religious about god OR security.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  22. TOO TIM COOK TO FAIL by Anonymous Coward · · Score: 0

    THE FATAL FLAW
    Apple Knew of FaceTime Issue Jan. 19; a 14-year-old in Arizona discovered the glitch that exposed millions of iPhone users to eavesdropping. His mother, a lawyer, exhausted every avenue she could to alert Apple. Told to become a developer to report bugs, it wasn’t until Monday that the company raced to disable Group FaceTime when a developer notified Apple.

    Its time... AAPL has lost sight of its primary reason d'être, principle customer and existential key to success. Tim Cook's first action when taking reigns over at Apple was to File13 all of SteveJobs direct contacts with influencers. That single action spoke volumes. Now here its final edict surfaces.

    Dump AAPL until new leadership arrives with the commitment, vision and ability to lead from the front.

    1. Re:TOO TIM COOK TO FAIL by ElitistWhiner · · Score: 1

      Two days later...

      iCloud bug ‘let ANYONE read your private iPhone notes’ – and was ‘kept a secret’, security expert claims.

      THIS is not validated nor verified yet, but if not FAKE news - TIM COOK's name is all over it.

  23. but Apple fans will find an excuse to believe in by Anonymous Coward · · Score: 0

    This sort of thing cracks me up when juxtaposed with the unshakable belief in Apple "security" held by many Apple users.

    Look at the stuff Jeff Atwood frequently gushes about the iPhone's "world class mobile hardware security"... hilarious!

    I have noticed that the real hardcore security guys fall into one of three camps: they either don't put anything personal or meaningful on their phones, or they use burners all the time, or they run android phones with custom-compiled kernels. Only the first group uses Apple products.

    If the FBI is not completely incompetent, they will always tell people they can't hack the phones they can hack, and vice versa. Obviously.

  24. Re:Bug or Feature by bobbied · · Score: 1

    So, you believe the moon landings where a hoax and Elvis is still alive, living as a dishwasher at Mel's diner in Backwater Mississippi... Let me guess, you know where Jimmy Hoffa is too. OK.. I get it. Facts don't matter all that much to you.. (sarc off)

    --
    "File to fit, pound to insert, paint to match" - Aircraft Maintenance 101
  25. Re: Bug or Feature by dougdonovan · · Score: 1

    apple should hire the 14 year old under the table then he could retire by the time he is 40ish.

  26. Re:Bug or Feature by Anonymous Coward · · Score: 0

    Look, Buddy, I'm going to believe whatever I want to believe, so don't go throwing around your pesky facts n' stuff. I already *know* I'm right.

  27. I noted THIS ve problem to him... apk by Anonymous Coward · · Score: 0

    I noted THIS very problem to him & he replied "it's already patched don't worry, Q/A timelag" - I'm not bs'ing @ all when I say what I do.

    * I doubt he'd lie to me (he's family & we tend to be pretty straight-up w/ one another, always have).

    APK

    P.S.=> Find out what an Apple "Tiger Team" is, & then get back to me (you'll 'change your tune')... apk

  28. IF you're smart? apk by Anonymous Coward · · Score: 0

    IF you're smart? You STOP working FOR OTHERS & go into business for YOURSELF (I was a dev 1994-2008 & I did it - it's BETTER (way better & you really only answer to YOURSELF & bills)).

    * He tells me there's guys that have been @ Apple for 10++ yrs. quite a lot (says they're "smart" & I tell him "Sure, seems that way NOW for YOU, but wait until YOU'VE been there 10++ yrs. - they'll just seem like guys that've been there a LONG TIME & have great specific domain (or non-specific & WIDE) know-how & SO WILL YOU by then").

    APK

    P.S.=> I have noted to him that when you "keep adding NEW 'features'" you also introduce room for error but that IS how the game is - to keep ahead of competition, you have to 'add' (personally, I'd take time to COMPLETELY shore-up & SECURE my OS, 1st - but that's me)... apk

  29. My code's in English so yes, lol... apk by Anonymous Coward · · Score: 0

    See subject & your "scribblings/droolings" look like "trollspeek", hahahaha!

    APK

    P.S.=> You PUNY worthless TROLL... apk

  30. Here's proof (days after I knew)... apk by Anonymous Coward · · Score: 0

    "fix that will be released in a software update later this week,â an Apple spokesperson told Threatpost https://threatpost.com/apple-d...

    * EAT YOUR WORDS!

    APK

    P.S.=> You TROLL CHUMP... apk